CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_PASSWORD` on a `pull_request` trigger
.github/workflows/pr_test_kcm_region_wi…:54
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_USERNAME` on a `pull_request` trigger
.github/workflows/pr_test_kcm_region_wi…:53
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_PASSWORD` on a `pull_request` trigger
.github/workflows/pr_test_tenant_isolat…:50
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_USERNAME` on a `pull_request` trigger
.github/workflows/pr_test_tenant_isolat…:49
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_PASSWORD` on a `pull_request` trigger
.github/workflows/pr_test_mgmt_upgrade.…:49
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_USERNAME` on a `pull_request` trigger
.github/workflows/pr_test_mgmt_upgrade.…:48
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_PASSWORD` on a `pull_request` trigger
.github/workflows/pr_test_kof_installat…:54
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_USERNAME` on a `pull_request` trigger
.github/workflows/pr_test_kof_installat…:53
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_PASSWORD` on a `pull_request` trigger
.github/workflows/pr_test_adopted_upgra…:73
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_USERNAME` on a `pull_request` trigger
.github/workflows/pr_test_adopted_upgra…:72
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_PASSWORD` on a `pull_request` trigger
.github/workflows/pr_test_cross_namespa…:50
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_USERNAME` on a `pull_request` trigger
.github/workflows/pr_test_cross_namespa…:49
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_PASSWORD` on a `pull_request` trigger
.github/workflows/pr_test_helm_chart.yml:101
CRIT
MINED116
Workflow uses `secrets.REGISTRY_CI_USERNAME` on a `pull_request` trigger
.github/workflows/pr_test_helm_chart.yml:100
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
kof-operator/webapp/collector/src/provi…:27
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
kof-operator/webapp/collector/src/compo…:216
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
kof-operator/webapp/collector/src/compo…:59
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
kof-operator/webapp/collector/src/compo…:382
HIGH
MINED033
[MINED033] Go Recover Without Log: defer func() { recover() }() that silently swallows pa…
kof-operator/internal/server/middleware…:71
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
kof-operator/internal/s3/s3client.go:133
HIGH
MINED014
[MINED014] Disabled Tls Verify: verify=False in requests, rejectUnauthorized:false in nod…
kof-operator/internal/s3/s3client.go:74
HIGH
SEC088
[SEC088] Go: TLS InsecureSkipVerify=true: tls.Config{InsecureSkipVerify:true} disables ce…
kof-operator/internal/s3/s3client.go:74
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
kof-operator/internal/acl/handlers/jaeg…:61
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
kof-operator/internal/acl/handlers/jaeg…:51
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
kof-operator/internal/acl/handlers/help…:104
HIGH
MINED108
`self.close` used but never assigned in __init__
scripts/victoria-migration/migration.py:308
HIGH
MINED108
`self.flush` used but never assigned in __init__
scripts/victoria-migration/migration.py:302
HIGH
MINED108
`self.finalize` used but never assigned in __init__
scripts/support-bundle-analyzer.py:95
HIGH
MINED108
`self.summary_codeblock` used but never assigned in __init__
scripts/support-bundle-analyzer.py:89
HIGH
MINED108
`self.line` used but never assigned in __init__
scripts/support-bundle-analyzer.py:88
HIGH
MINED108
`self.line` used but never assigned in __init__
scripts/support-bundle-analyzer.py:66
HIGH
MINED108
`self.line` used but never assigned in __init__
scripts/support-bundle-analyzer.py:65
HIGH
COMP001
[COMP001] High cognitive complexity: Function `check_helmreleases` has cognitive complexi…
.agents/skills/troubleshoot/scripts/ste…:18
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/pr_test_adopted_upgra…:53
HIGH
MINED115
Action `pozetroninc/github-action-get-latest-release` pinned to mutable ref `@master`
.github/workflows/pr_test_adopted_upgra…:27
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v6`
.github/workflows/pr_check_values_consi…:23
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/pr_check_values_consi…:20
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/pr_test_cross_namespa…:166
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v6`
.github/workflows/pr_test_cross_namespa…:141
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v6`
.github/workflows/pr_test_cross_namespa…:88
HIGH
MINED115
Action `pozetroninc/github-action-get-latest-release` pinned to mutable ref `@master`
.github/workflows/pr_test_cross_namespa…:37
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/pr_test_cross_namespa…:31
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/pr_test_cross_namespa…:27
HIGH
MINED115
Action `actions/github-script` pinned to mutable ref `@v9`
.github/workflows/triage.yaml:63
HIGH
MINED115
Action `actions/github-script` pinned to mutable ref `@v9`
.github/workflows/triage.yaml:46
HIGH
MINED115
Action `actions/github-script` pinned to mutable ref `@v9`
.github/workflows/triage.yaml:29
HIGH
MINED115
Action `actions/github-script` pinned to mutable ref `@v9`
.github/workflows/triage.yaml:16
HIGH
MINED115
Action `pozetroninc/github-action-get-latest-release` pinned to mutable ref `@master`
.github/workflows/pr_test_helm_chart.yml:88
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/pr_test_helm_chart.yml:82
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/pr_test_helm_chart.yml:77
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/pr_test_helm_chart.yml:61
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/pr_test_helm_chart.yml:42
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/pr_test_helm_chart.yml:29
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/pr_test_helm_chart.yml:24
HIGH
MINED115
Action `goreleaser/goreleaser-action` pinned to mutable ref `@v7`
.github/workflows/release_images.yml:58
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/release_images.yml:31
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/release_images.yml:24
HIGH
MINED115
Action `ytanikin/pr-conventional-commits` pinned to mutable ref `@1.5.2`
.github/workflows/pr_conventional_commi…:12
HIGH
MINED118
Dockerfile FROM `linuxcontainers/debian-slim:latest` not pinned by digest
docker/opentelemetry-collector-contrib/…:2
HIGH
MINED118
Dockerfile FROM `otel/opentelemetry-collector-contrib:0.143.0` not pinned by digest
docker/opentelemetry-collector-contrib/…:1
HIGH
MINED131
pre-commit hook `https://github.com/norwoodj/helm-docs` pinned to mutable rev `v1.14.2`
.pre-commit-config.yaml:17
HIGH
GO-2026-5039
stdlib: GO-2026-5039
kof-operator/go.mod
HIGH
GO-2026-5038
stdlib: GO-2026-5038
kof-operator/go.mod
HIGH
GO-2026-5037
stdlib: GO-2026-5037
kof-operator/go.mod
HIGH
GHSA-qcvw-82hh-gq38
istio.io/istio: GHSA-qcvw-82hh-gq38
kof-operator/go.mod
HIGH
GHSA-hqxw-mm44-gc4r
istio.io/istio: GHSA-hqxw-mm44-gc4r
kof-operator/go.mod
HIGH
GHSA-856q-xv3c-7f2f
istio.io/istio: GHSA-856q-xv3c-7f2f
kof-operator/go.mod
HIGH
GHSA-7774-7vr3-cc8j
istio.io/istio: GHSA-7774-7vr3-cc8j
kof-operator/go.mod
HIGH
GO-2026-5033
golang.org/x/crypto: GO-2026-5033
kof-operator/go.mod
HIGH
GO-2026-5023
golang.org/x/crypto: GO-2026-5023
kof-operator/go.mod
HIGH
GO-2026-5021
golang.org/x/crypto: GO-2026-5021
kof-operator/go.mod
HIGH
GO-2026-5020
golang.org/x/crypto: GO-2026-5020
kof-operator/go.mod
HIGH
GO-2026-5019
golang.org/x/crypto: GO-2026-5019
kof-operator/go.mod
HIGH
GO-2026-5018
golang.org/x/crypto: GO-2026-5018
kof-operator/go.mod
HIGH
GO-2026-5017
golang.org/x/crypto: GO-2026-5017
kof-operator/go.mod
HIGH
GO-2026-5016
golang.org/x/crypto: GO-2026-5016
kof-operator/go.mod
HIGH
GO-2026-5015
golang.org/x/crypto: GO-2026-5015
kof-operator/go.mod
HIGH
GO-2026-5014
golang.org/x/crypto: GO-2026-5014
kof-operator/go.mod
HIGH
GO-2026-5013
golang.org/x/crypto: GO-2026-5013
kof-operator/go.mod
HIGH
GO-2026-5006
golang.org/x/crypto: GO-2026-5006
kof-operator/go.mod
HIGH
GO-2026-5005
golang.org/x/crypto: GO-2026-5005
kof-operator/go.mod
HIGH
SEC020
[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-b…
kof-operator/internal/server/handlers/p…:79
HIGH
SEC020
[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-b…
kof-operator/internal/server/handlers/m…:224
HIGH
SEC020
[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-b…
kof-operator/internal/server/handlers/k…:33
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
kof-operator/internal/server/server.go:91
MED
MINED111
Bare except continues silently
.agents/skills/troubleshoot/scripts/ana…:41
MED
MINED111
Bare except continues silently
scripts/victoria-migration/migration.py:415
MED
MINED111
Bare except continues silently
scripts/support-bundle-analyzer.py:857
MED
MINED111
Bare except continues silently
scripts/support-bundle-analyzer.py:433
MED
MINED111
Bare except continues silently
scripts/support-bundle-analyzer.py:573
MED
MINED111
Bare except continues silently
scripts/support-bundle-analyzer.py:420
MED
MINED111
Bare except continues silently
scripts/support-bundle-analyzer.py:278
MED
MINED111
Bare except continues silently
scripts/support-bundle-analyzer.py:133
MED
MINED111
Bare except continues silently
scripts/support-bundle-analyzer.py:18
MED
MINED111
Bare except continues silently
scripts/check_values_consistency.py:184
MED
MINED111
Bare except continues silently
scripts/check_values_consistency.py:145
MED
MINED111
Bare except continues silently
scripts/check_values_consistency.py:96
MED
COMP001
[COMP001] High cognitive complexity: Function `main` has cognitive complexity 17 (SonarSo…
.agents/skills/troubleshoot/scripts/ana…:46
MED
DKR003
Dockerfile base image uses the latest tag
docker/opentelemetry-collector-contrib/…:3
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
DEPCUR-NPM
npm package `shadcn` is 2 major version(s) behind (2.10.0 -> 4.10.0)
kof-operator/webapp/collector/package.j…
MED
DEPCUR-NPM
npm package `jsdom` is 3 major version(s) behind (26.1.0 -> 29.1.1)
kof-operator/webapp/collector/package.j…
MED
DEPCUR-NPM
npm package `globals` is 3 major version(s) behind (14.0.0 -> 17.6.0)
kof-operator/webapp/collector/package.j…
MED
DEPCUR-NPM
npm package `@vitejs/plugin-react` is 2 major version(s) behind (4.7.0 -> 6.0.2)
kof-operator/webapp/collector/package.j…
MED
DEPCUR-NPM
npm package `@eslint/js` is 1 major version(s) behind (9.39.4 -> 10.0.1)
kof-operator/webapp/collector/package.j…
MED
DEPCUR-NPM
npm package `recharts` is 1 major version(s) behind (2.15.4 -> 3.8.1)
kof-operator/webapp/collector/package.j…
MED
DEPCUR-NPM
npm package `dexie-react-hooks` is 3 major version(s) behind (1.1.7 -> 4.4.0)
kof-operator/webapp/collector/package.j…
MED
MINED124
requirements.txt: `pyyaml` has no version pin
scripts/requirements.txt:4
MED
MINED124
requirements.txt: `tqdm` has no version pin
scripts/requirements.txt:3
MED
MINED124
requirements.txt: `requests` has no version pin
scripts/requirements.txt:2
MED
MINED124
requirements.txt: `pytest` has no version pin
scripts/requirements.txt:1
MED
GHSA-58qx-3vcg-4xpx
ws: GHSA-58qx-3vcg-4xpx
kof-operator/webapp/collector/package-l…
MED
GHSA-v2v4-37r5-5v8g
ip-address: GHSA-v2v4-37r5-5v8g
kof-operator/webapp/collector/package-l…
MED
GHSA-jxxr-4gwj-5jf2
brace-expansion: GHSA-jxxr-4gwj-5jf2
kof-operator/webapp/collector/package-l…
MED
GHSA-xwx5-5c9g-x68x
istio.io/istio: GHSA-xwx5-5c9g-x68x
kof-operator/go.mod
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
kof-operator/internal/coldstorage/vmcli…:131
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
kof-operator/internal/telemetry/telemet…:79
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
kof-operator/internal/audit/manifest.go:70
LOW
COMP001
[COMP001] High cognitive complexity: Function `load_yaml_list` has cognitive complexity 8…
.agents/skills/troubleshoot/scripts/lib…:36
LOW
DEPCUR-NPM
npm package `eslint-plugin-react-refresh` is minor version(s) behind (0.4.26 -> 0.5.2)
kof-operator/webapp/collector/package.j…
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/provi…:31
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:20
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:2
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:8
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:229
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:186
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:74
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:4
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:2
LOW
AIC003
Duplicated implementation block across source files
kof-operator/webapp/collector/src/compo…:10
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/controller/vmstor…:1
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/controller/promxy…:4
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/controller/promxy…:1
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/controller/config…:156
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/controller/cluste…:1
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/coldstorage/vtrac…:134
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/coldstorage/expor…:46
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/acl/handlers/prom…:52
LOW
AIC003
Duplicated implementation block across source files
kof-operator/internal/acl/handlers/jaeg…:54
LOW
AIC003
Duplicated implementation block across source files
kof-operator/api/v1beta1/zz_generated.d…:1
LOW
AIC003
Duplicated implementation block across source files
kof-operator/api/v1beta1/vmstorageconne…:3
LOW
AIC003
Duplicated implementation block across source files
kof-operator/api/v1beta1/vmstorageconne…:1
LOW
AIC003
Duplicated implementation block across source files
kof-operator/api/v1beta1/promxyservergr…:1
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
kof-operator/webapp/collector/webapp.go:17
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
kof-operator/webapp/collector/src/provi…:11
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
kof-operator/webapp/collector/src/datab…:34
INFO
MINED056
[MINED056] React Key As Index: key={index} in map() — re-renders the wrong elements on re…
kof-operator/webapp/collector/src/compo…:191
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
kof-operator/cmd/cold-storage-exporter/…:39
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
kof-operator/cmd/audit-logs-exporter/ma…:39
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
kof-operator/cmd/acl/main.go:81
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
kof-operator/api/v1beta1/vmstorageconne…:8
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
kof-operator/api/v1beta1/promxyservergr…:8
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
kof-operator/api/v1beta1/groupversion_i…:8
INFO
DEPCUR-NPM
npm package `@radix-ui/react-slot` is patch version(s) behind (1.2.3 -> 1.2.4)
kof-operator/webapp/collector/package.j…
INFO
DEPCUR-NPM
npm package `@radix-ui/react-label` is patch version(s) behind (2.1.7 -> 2.1.8)
kof-operator/webapp/collector/package.j…